Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3194 articles · 168073 vulns · 37/41 feeds (7d)
165,585 vulnerabilities total
7.8
linux · CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-placeKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
121🔥
84 art.
0
Apr 22, 2026
10.0
cis · CVE-2026-20127 — Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityKEVEXPLOITEDPATCHED
catalyst_sd-wan_manager· CVSS 10.0· CWE-287
121🔥
17 art.
0
Feb 25, 2026
8.8
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsKEVEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
116🔥
41 art.
0
May 8, 2026
7.8
linux · CVE-2026-43500 — rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
110🔥
28 art.
0
May 11, 2026
10.0
ui · CVE-2026-34908 — CVE-2026-34908: A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS deKEVEXPLOITEDPATCHED
unifi_os_server· CVSS 10.0· CWE-284
97
9 art.
0
May 22, 2026
—
ptc · CVE-2026-12569 — Remote Code Execution (RCE) vulnerability in Windchill PDMlinkEXPLOITEDPATCHED
flexplm· CWE-20
96
8 art.
0
Jun 18, 2026
10.0
ui · CVE-2026-34909 — CVE-2026-34909: A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to aKEVEXPLOITEDPATCHED
unifi_os_server· CVSS 10.0· CWE-22
92
5 art.
0
May 22, 2026
9.8
geoserver · CVE-2024-36401 — GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code ExecutioKEVEXPLOITEDPATCHED
geoserver· CVSS 9.8· CWE-95
85
1 art.
0
Jul 1, 2024
7.1
mappress · CVE-2026-56011 — WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerabilityKEVEXPLOITED
mappress maps for wordpress· CVSS 7.1· CWE-79
82
1 art.
0
Jun 26, 2026
8.6
igniterealtime · CVE-2023-32315 — Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setuKEVEXPLOITEDPATCHED
openfire· CVSS 8.6· CWE-22
82
1 art.
0
May 26, 2023
7.1
linux · CVE-2026-46333 — ptrace: slightly saner 'get_dumpable()' logicEXPLOITEDPATCHED
kernel· CVSS 7.1· CWE-362
78
19 art.
0
May 15, 2026
9.2
libssh2 · CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cEXPLOITEDPATCHED
libssh2· CVSS 9.2· CWE-680
75
8 art.
0
Jun 17, 2026
8.6
cis · CVE-2026-20230 — CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session MaEXPLOITEDPATCHED
unified_communications_manager· CVSS 8.6· CWE-918
75
19 art.
0
Jun 3, 2026
7.8
cis · CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation VulnerabilityEXPLOITEDPATCHED
catalyst_sd-wan_manager· CVSS 7.8· CWE-116
74
21 art.
0
Jun 4, 2026
9.9
langflow · CVE-2026-55255 — Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowKEVEXPLOITEDPATCHED
langflow· CVSS 9.9· CWE-639
69
2 art.
0
Jun 19, 2026
7.5
gpac project · CVE-2025-60474 — CVE-2025-60474: A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 alloEXPLOITED
mp4box· CVSS 7.5
68
2 art.
0
Jun 24, 2026
7.8
linux · CVE-2026-46300 — net: skbuff: preserve shared-frag marker during coalescingEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
68
19 art.
0
May 13, 2026
8.8
google · CVE-2026-13033 — CVE-2026-13033: Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker EXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-125
66
5 art.
0
Jun 24, 2026
8.8
google · CVE-2026-13038 — CVE-2026-13038: Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbiEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-416
66
5 art.
0
Jun 24, 2026
8.2
jqlang · CVE-2026-39979 — jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted BuffersEXPLOITEDPATCHED
jq· CVSS 8.2· CWE-125
65
5 art.
0
Apr 13, 2026